ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

The future of IT security is fewer walls, not more

Dan Ilet ZDNet.co.uk

Published: 07 Apr 2005 17:35 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

IT security doesn't work very well. Firewalls supposedly repel invaders — apart from those that get through the necessary holes and into the constantly compromised software behind.

The inconvenience of shoring up security infrastructures is restricting the evolution of the extended business. Something needs to change and the UK security user group the Jericho Forum believes it has the answer.

The roving gang of European chief information security officers claims the key to better security is less walls not more — a concept they call deperimeterisation. De-P is ugly shorthand for the recognition that you can't do business if you hide behind walls. As the city of Jericho found out in the sixth book of Joshua, walls fall down.

But if you can't hide, what can you do? Trust and verify. Establish those whom you trust. Verify that they are who they say they are. Make sure they only have access to data they need. Ignore everything else.

Security is a process not a product, says Jericho, and an open process at that. Establish open standards for identity management, digital rights, encryption and data-level authentication, and we can eventually do away with the rest of the security infrastructure altogether while maintaining commercial and operational flexibility.

This will take a while. But because the Jericho Forum is user-led, it is honest about the problems and pragmatic about a gradual introduction of these ideas. ZDNet UK spoke to one of Jericho's founders, Paul Simmonds, global information security director of chemical giant ICI, about the ideas behind deperimeterisation and pushing the organisations unique take on security to the US.

Q: What makes Jericho different from other security groups?
A: First and foremost, it’s user driven. Secondly, it addresses areas that no one else does. We were very careful when we formalised it. We did very extensive Web searches to determine that no one else was addressing the problem.

And what exactly is the problem, as you see it?
My rant at the moment is that the security industry is not learning from its mistakes. If you don’t learn from your mistakes, you’re not going to move forward. We are still designing new systems — pick any vendor, get feedback from a consultant and it’ll be full of insecure protocols hidden behind a firewall. People are still working on the concept of an essentially structured perimeter design. We’ve got to shake off that mentality. That is the challenge for the security industry — bottom line. If you want to be employed in this industry, you’re going to need to have that mindset. That’s key to what is going on- shifting that mindset. We said from day one, this [the Jericho Forum] was about starting a discussion. If you want to know where we’ve gone — it’s now about shifting the mindset.

Next

Previous

1 2 3


  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
202 out of 425 people found this useful


Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Head of Business Analysis - Glasgow - Permanent

To succeed, you will need a proven track record in a similar leadership role within a change management environment. This is an exciting time to join ...

IBM opportunities

You may decide to specialise in the design concept of a solution and become an IT Architect; you may enjoy technology leadership and move into ...

Oracle technical team lead, System Implementations,Financial Co.

This opportunity is seeking an individual with a balance between hands-on technical database development (Oracle) and team leadership/management. ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Speed Demon: Wireless Surpasses...

Mobile Speed Demon: Wireless Surpasses Landline Author: Eric Everson, Founder MyMobiSafe.com As I look around my house and throughout my network of friends, I instantly realize... More

Post a comment

Why do you need Portable password mana...

There are much more than 5, but I will start with these main points: 1. You are human... never mind, no one is perfect. 2. We live in modern world with its cons and pros 3. We... More

Post a comment

The GoDaddy saga continues...

I've been trying to sort out an incident with registrar GoDaddy since last week. I blogged on Tuesday and Thursday about the situation, but in a nutshell I found out that I was registered... More

1 comment